Evolution of Auditing: A Historical Analysis
Evolution of Auditing: A Historical Analysis
2
effectiveness, performance audit, management audit, risk audit and systems audit.
3. Internal audit is presently viewed as a largely negative and fault finding activity
which seeks to curtail and crosscheck rather than to offer positive
recommendations. It has to transcend this identity and establish itself as an aid
to governance. The aim of internal audit is to add value to management and to
help the executive or the ‘client’ in achieving the stated goals of the organization.
4. In the context of the paradigm shift from inputs to outputs and outcomes and in
the context of recent initiatives like outcome budgeting internal audit has
emerged as a crucial tool which can play an important role towards ensuring the
achievement of the outcomes. Internal audit can provide valuable mid course
corrections as it is ideally placed to provide a concurrent evaluation of schemes
and projects at different stages of implementation.
5. Internal audit has also emerged as an extremely valuable tool for the government
in view of the increasing stress on accountability and transparency in the
sphere of public governance the world over. This trend is typified in India in the
form of the Fiscal Responsibility and Budget Management Act and the Right to
Information Act.
6. Audit should not be merely ensuring adherence to standards but should be
proactively advocating the formulation and refining of standards on a
continuous basis.
7. The internal audit reporting should be accurate, timely, and reliable and
should have integrity so that it can support decision making.
8. Rather than any perceived conflict between internal audit and external audit,
internal audit has to position itself as a complementary to statutory audit.
9. The issues of ownership and empowerment of internal audit are important
issues that need to be addressed in order to make the internal audit system
strong and independent. There is need for a fresh mandate
3
for internal audit which is formalized and legalized at the level of the top executive. In
this context the Finance Secretary in his speech in the concluding session
assured the CGA of a most favorable and sympathetic consideration at the
highest level. He made it his responsibility to see that before the fiscal is out CGA
will have a formal mandate in the charter of responsibility which could then be
further evolved.
10. Capacity building and skill upgradation are of vital importance to internal audit
today especially in view of the vast changes that have happened in the sphere of
technology and financial management. Internal audit has to keep pace with these
changes if it is to establish itself as a positive force in government. In this context
the Finance Secretary in his speech at the seminar very generously promised the
CGA a sum of rupees 10 crore for this purpose. He also indicated that CGA’s
office could send several groups of officers to various countries to study
international best practices that could be replicated in the Indian context. The
Finance Secretary concluded with three resolutions:
i. One: today we will disperse with a determination to make internal audit more
efficient, value adding, and formally mandated in the governance of this country.
ii. Two: that we will build our capacity to do things better with skills which may not
exist with us today; for this we will tap both national and international resources
iii. Three: the negative perception, which sometimes get attached to finance people
would soon be turned into a matter of the past and people shall look at us as a
resource, as a human capital, that is adding value not only to the concept or
design of schemes but also in their implementation in order that we hand over to
the next generation a better government, and a better India.
4
Session I
Global Perspectives on Evolution of Internal Audit in the Public Sector
The first session in the Seminar on ‘Improving the effectiveness of Internal Audit in
Government of India’ was on Global Perspectives on Evolution of Internal Audit in
the Public Sector. The session was chaired by Shri S W Oak, Controller General of
Accounts. The speakers were Ms. Carman Young, Auditor General, The World Bank,
and Mr. Thomas Warga, then Chairperson, the Institute of Internal Auditors, USA, and
Senior Vice President & General Auditor of the New York Life Insurance Company.
The session began with the CGA addressing the status of internal audit in the
Government as it exists today, and the challenges that it faces. He spoke about the lack
of ownership and empowerment of internal audit. Placing the role of internal audit in the
context of the shift from the preoccupation with inputs to outputs, he said that until now,
all we have been doing is to check whether the procedures and systems are as laid
down by us are being followed, but now the time has come to move ourselves beyond
compliance and procedural audit.
Commencing the technical session, Mr. Thomas Warga began with an overview of the
evolution of internal auditing in public sector. He spoke about the experiences in the
Office of the Controller General in Canada in improving internal audit in the Federal
Government of Canada. He commented on the current global theme for change and
modernization of government and increased accountability. This theme has two specific
contexts. An organizational structure for accountability i.e. clear delineation of
responsibilities and adapting to a modern internal control framework. Greater delegation
of responsibilities and decreasing centralization has also necessitated a renewed
internal control system.
This was reflected in Europe in the 90s when the OECD and the European Commission
established modernizing norms for the governments of Eastern and Central Europe
under the aegis of the Central Harmonisation Unit which was aimed at getting their legal
and institutional frameworks instep with the rest of Europe before entering into the
European Commission. This resulted into their having a very strong internal audit within
the public sector. South Africa too has gone through tremendous change in this respect.
Citing the case of Taiwan, he commented that Taiwan has a strong history of the
Controller General’s Office and a strong representation of internal audit.
An important aspect that he mentioned was that of a public sector governance model
within the government structure with stress on the policies and procedures to direct
activities and to provide reasonable assurance that their objectives were being met. This
would ensure the quality and equity of services for the
1
stakeholders, the citizens. It would also reduce the risk of public corruption through
accountability. Important principles for public sector governance are openness, and clear
communication of information.
The other guiding principles for the new governance model in the modernization of
governments are integrity, and objectivity for services and stewardship of public funds.
How money is spent requires an effective internal control framework because there is a
shift from the old traditional control or the central control, all expenses pre-approved to a
delegation, to a more distributive control where management is responsible after
checking and monitoring.
Further, he spoke about principle of accountability. Internal audit can play a clear role in
all of these. This could be a public sector governance model, which is quite similar to the
models in the private sector. This model is responsible for supporting management and
executive side but it is not dependent on them to do their job. It is independent but also
provides services to management. It could therefore be called an equal relationship. It
supports the oversight group, which could be an audit committee, or supreme audit
institute or a supervising body, or it could be a legislative body for the central
government and it helps them perform their duties of oversight. It helps the management
to do their job and gives them feedback and ideas for improvement in running the
business or the department, on a day-to-day basis. The bond that holds all this together
is an internal control framework that is easily understood.
The control framework for public sector focuses on financial and performance side, and
there is a shift from the preventive to the effective side. This could also be seen as a
shift from pre-authorizing payments and very tightly controlled budgets on the input side
to the output side and monitoring through data, through trend setting and through the
audit process. It clearly defines responsibility of management and shifts more
responsibility to it. But in order for it to work the key ingredient is reporting and
monitoring and having clear standards so that it can be benchmarked and measured.
The modern control framework deals with performance in government and the quality
improvement process of the 1980s is a key factor here on measuring performance. It
was about responsiveness to the stakeholders, the user of government services and
accountability to them and it also involves performance audits by internal auditors in the
government sector. So not only do they do financial audits but they also do operational
audits in addition to compliance audits.
He then spoke about the New York State experience, where they started in 1987 with
the Internal Control Act which warranted over 250 government agencies to apply and
establish effective internal control system. He also briefly mentioned the IIA code of
ethics, which has four core principles of integrity, objectivity, confidentiality and
competence.
2
Mr. Warga also introduced the Certification in Control Self-Assessment, and the Certified
Financial Service Auditors which are very popular because of the internal control
assessments that are required in certifications. They are popular in areas where strong
financial service auditors are needed. The Certified Government Auditing Professional
Exam is designed for the public sector internal audit practitioner. It tests knowledge of
public sector auditing for fund accounting, grants, legislative oversight, privacy, or
confidentiality rights, performance measures. It emphasizes the accountability to the
public and improving government services.
He then briefly spoke about the Institute of Internal Auditors, and the work they do for
internal auditing. He mentioned how the New York Stock Exchange recognizes the
profession of Internal Auditors, as an example. They require all listed companies to have
an internal audit function. South Africa recognizes the Institute of Internal Auditors
standards and required that the government auditors follow the Institute of Internal
Auditors standards. The IIA also has a memorandum of understanding with IFAC on how
they are going to evolve and get our standards endorsed by IFAC and they have
members of IFAC on their technical committees and having members from the Institute
of Internal Auditors join theirs.
He then came to the issue of what is important to the public sector. He admitted that
standards may need to be adjusted for the public sector .Finally, he came to the issue of
Capacity planning, which basically provides the resources to help and develop internal
infrastructure in developing areas around the world such as Africa, a sphere in which IIA
was doing some path breaking work. He took the example of China who have come
online and are very interested in improving the quality of internal auditing in the private
and the public sector and the number of people sitting for the exam has skyrocketed.
Ms. Carman Young initiated her talk with some observations on the collaborative efforts
between the World Bank and the government of India in advancing the role of internal
audit in government. The technical aspect of her talk centered on the government
capability maturity model for internal audit that has been developed by the Government
Relations Committee in the Institute of Internal Auditors and it’s applicability to India.
Ms. Young spoke of the role of the World Bank in the broader context of her perception
of the changes in India in the recent years. While she was deeply appreciative of the
progress in terms of socio-economic indicators, she also cautioned of the grave
problems that India still faces in the areas of economic disparity, poverty, healthcare,
education .Ms Young spoke of the action plan of the World Bank being closely aligned
with the stated goals of Government of India to try and address some of these critical
issues over the next few years.
3
With specific reference to the IDF grant in this broad context, Ms. Young emphasized the
criticality of the financial management reforms that have been initiated under this grant in
the areas of Classification reforms, accrual accounting and Internal Controls and Internal
Audit. Echoing the views of the CGA, Ms. Young agreed that these reforms are
interconnected and finally dependent for their success on ownership from the executive.
Tracing the evolution of the role of internal audit in government briefly, starting from a
limited compliance audit role in the 1980.s to the present, when the Internal auditing
function has in her opinion become a major value addition to an organization and the
executives. Not only have internal auditors grown in competence, but the senior
executives have also become deeply engaged with the role of internal audit.
Talking at length about the capability maturity model, Ms. Young explained that it is an
analytical tool that basically talks about five levels of maturity of the internal auditing
function in government ranging from entry on the left hand column over to mature or
world class government internal auditing organization in five basic areas including
governance, standards, structure, people management aspects, and the service focus of
internal auditing.
At level one or the entry level, governance is ad- hoc and reporting is at management
discretion. Internal does not have a formal mandate. In terms of standards, there are
very few standards being used. Further there are no policies, procedures or manuals of
internal audit. The structure of the internal audit organization is ad-hoc and temporary.
Skills and tools are very basic. Audit is largely transaction or compliance based. Level
two is relatively a more advanced model with most of the characteristics of level one.
Moving to Level, Ms. Young described it as a more mature internal audit model where
the internal audit functions is seen as mandatory. Internal audit reports to a Department
head and there is also an audit committee comprising senior management. There are
clear cut standards, procedures and manuals. Auditors are professionally qualified and
sophisticated tools and audit software are being used. At this stage internal audit has a
high much higher level of quality assurance and contributes in a significant way to the
value addition of an organization. In terms of services focus internal audit moves from
merely compliance to performance audit and also is in a position to perform risk
assessment in terms of internal controls and to provide positive assurances in terms of
the business processes. Moving up on the maturity model, Ms. Young took the
discussion to the mature, world class level, which is in all respects the acme of the
internal audit function. By this time internal audit has force of legislation. It is managed
by an independent audit committee made up of specialists in the field who are
responsible for appointing the head of internal audit. Internal audit is also self sufficient
financially with a separate budget. There
4
is legislated compliance of standards and most significantly audit moves away from
merely reporting inputs to outcomes.
Viewed in terms of skills, not only do the internal auditors possess specialized skills but
are also in apposition to outsource special skill requirements that they may not possess.
Further audit is not only providing risk assessment, assurance on processes and
systems, consulting and strategic planning but are involved in governance aspects of
ethics and accountability frameworks in the organization. They have full access to all
records and staff of the organization.. This a big step in ensuring accountability of the
organization
Ms. Young concluded the session by describing the pilot on internal audit that was
carried out in Kenya as part of the Global capacity Development Task Force that the IIA
was involved in. Ms. Young has also been closely involved in this on behalf oft the World
Bank. She termed it a great success, owing to the enthusiasm shown by the Kenyan
government. The IIA and World Bank were able to provide training to internal auditors,
help them develop risk based audit plans etc
Ms. Young concluded by drawing an analogy with the Government of India and their
plans to modernize and strengthen internal audit. Extending the cooperation of the World
Bank and the IIA in this endeavor she said that she was hopeful that .the proceedings of
the seminar would reveal the concrete plans of the CGA and other participants in this
direction.
Important recommendations:
• There is lack of ownership and empowerment of internal audit
• There is a shift in emphasis from inputs to outputs, correspondingly internal
audit has tom also shift from compliance and procedural audit.
• There is a global thrust for change and modernization of governments.
Three important components are clear delineation of responsibilities,
greater accountability and a modern internal control framework.
• New public sector governance model is needed with stress on integrity and
objectivity. Important principles for public sector governance are openness
and clear communication.
• Internal audit can play a role in all of these areas because monitoring and
reporting are vitally important to the success of this model and internal
audit can very ably perform that role.
5
• The internal control framework for public sector focuses on the financial and
performance side with a shift from the preventive to the effective side.
• Internal audit standards need to be adjusted for the public sector.
• Financial management reforms that have been initiated in India are of an
extremely critical nature and require executive support to succeed.
• The capability maturity model is an analytical tool that talks about five levels
of maturity of the internal auditing function in government ranging from
entry on the left hand column over to mature or world class government
internal auditing.
.
6
Annexure I
IA
Assurance & Advice that Bring Our Dream Closer 8
Capability Maturity
Model + Governance, ethics, accountability;Full access;Adding
valueRisk mgmt, consulting,& assurance; Strategic PlanAssurance on
Processes, systems; risk assessed planAdd Fin Controls, some
performanceTransactions, forensic, & complianceService
FocusSpecialized
skills, plus OS, CIA requiredDiverse skills, CAE is
CIA, PD providedPD supported, provide tools & softwareSome PD & core
audit competencyBasic Skills & Tools, no PD requiredPeople MgmtAC
involved in hiring/assessingCentral + IntegDeputy LevelCentral Core +
DecentralizedSrMgrDecentralizedSome Core Middle Mgr
UnitsDecentralizedAd HocTemporaryDiscretionaryStructureLegislated
Compliance, rep outcomesFull Stds, Int& Ext QA, track outcomeManuals,
Stds, QA, E/E MeasuresSome Stds, Review,BasicMeasuresNo Stds,
Policies,MeasuresStandardsLegislatedIndeptA/CCentral BudgetCabinet
OrderA/C Chair DHA/C BudgetMandatoryRep Dept HdSrMgmt A/CMgmt
support annual budgetMgmt A/CAd Hoc reporting at mgmt
discr.Governance5.
Mature World Class4. Meets All
Stds3. Meets Some Stds2.ManagedFunction1.
EntryCore Elements
7
Session II
Current Status of Internal Audit and Organizational Constraints
In the Government of India
For the second session of the Seminar, the panel speakers were Shri Jnan Prakash,
Controller General of Defence Accounts, Shri C R Sundaramurti, Addl Controller
General of Accounts, and Shri Shivaji Rakshit, Executive Director, Accounts, Ministry of
Railways.
The session commenced with a presentation by Shri Jnan Prakash. He started by
briefly introducing the Indian Defence Accounts Service (IDAS), which traces its
ancestry, from the East India Company. Moving on to the history of audit in the IDAS, he
explained that the mandate for audit in the IDAS is derived from the military finance
department in India, which was working under the crown. Later when the Comptroller
and Auditor General was appointed the supreme audit authority in India, it was decided
that the Controller General of Defence Accounts would function as sub audit officer to
the Comptroller and Auditor General.
The Controller General of Defence Accounts renders an annual audit certificate along
with the appropriation accounts for the Ministry of Defence, which are countersigned by
the Comptroller and Auditor General and placed in Parliament. The accounts include the
details of serious observations made by the CGDA and are part on the annual audit
certificate. It also contains various reviews of accounts
The offices of the CGDA which carry out these functions are generally co-located with
the Defence formations of the Army, Navy, Air Force, and also with the subsidiary
formations like coast guards, and the canteen stores department.
While describing the audit procedures, he said that the sanctions for expenditure are
audited first in the Ministry of Defence. Concurrence by the internal financial advisor
does not ensure that the sanction will not be subject to further audit. For the sanctioned
expenditure and the delegated power, there exists post audit.
There is an audit of consumption also. Audit of consumption is provided in the Defence
services, as various scales of consumptions have been prescribed for everything. There
is also a cash audit both for receipt and expenditure. Such reviews are carried out to
assess proper utilization of funds.
Sh. Jnan Prakash also described at length the process of audit reporting. At the first
stage, the audits of all transactions are reported to the formation headquarters. The
formation headquarters are responsible for ensuring that the lacunae pointed out in the
audit are examined and care is taken to improve their system. They in turn render a
report in this regard to their higher formations. The settlements of these audit
observations are of two types. First, where the audit
1
authorities satisfy themselves with the action taken by the formations that adequate
measures have been taken to ensure that mistakes committed are not repeated. The
second type of regularization involves obtaining the necessary sanctions by the lower
formations from the competent authorities for regularizing certain transactions.
The second type of reporting is for major financial and accounting irregularities. Out of
the observations that are raised, a quarterly report is compiled which includes major
financial and accounting irregularities. These are sent to the command headquarters in
the forces, and are taken seriously. And the action points are followed up rigorously.
Another half-yearly report is generated, which is called an internal audit report, and is
presented to the Ministry of Defence. The internal audit report takes into account not
only the items which have been included in the major financial and accounting
irregularity reports but also other procedural lapses, which have been noticed during the
audit of the formations. The Ministry of Finance are also provided a copy of this report
and appraised of the action taken on such issues.
The CGDA have undertaken performance audit of certain activities in consultation with
the executive for which the audit reports were separately submitted. Since this
performance report does not fall within the ambit of the regulatory audit, which is
required by the C&AG, it becomes a management information activity provided by the
CGDA to the executive. Sh. Prakash raised the extremely pertinent point that their aim
was to reduce the risks involved in decisions taken by the executive. The audit provides
data regarding cost of activities and the implications of the decisions taken by them. The
CGDA are also planning to move towards management audits.
He briefly also mentioned that the largest component of CGDA audit comprises cost
audit. The Ordnance factory board consisting of 39 ordinance factories with a turn over
of about Rs.8000 crores provides a vast opportunity and challenge for conducting cost
audit.
The session was then addressed by [Link] Rakshit, who spoke largely about the
prevalent operations of the Indian Railways with special reference to audit of revenue
generation. This, according to him was very different from the audit of the expenditure
that we see so commonly.
He then provided a detailed picture of the revenue generation in the Ministry of
Railways, and how audit is involved in tediously tracking the money, so that there is no
mismatch in the figures.
The final speaker for the session was, Shri C R Sundaramurti who began with an
overview of the formation and the functions of the Indian Civil Accounts Service, and the
Organisation of the Controller General of Accounts. At the time of Departmentalisation,
the responsibility for the preparation and consolidation of
2
the Union Government accounts were entrusted to the Controller General of Accounts,
along with the responsibility for establishing and maintaining a technically sound
accounting system in the departmentalized accounts offices.
The CGA was also empowered to inspect the departmentalized accounts officers, and
thus the powers of the CGA to inspect the departmentalized accounts offices extends
beyond the Ministry of Finance and to the different organizations. When the accounts
were internalized with the Ministries, the Secretaries of the Ministries were made the
Chief Accounting Authority. This, according to him was good corporate practice, as the
buck has to stop at the top. The system envisaged in 1976 with the approval of the
cabinet, (which had come much earlier in 1973-74), required that each Ministry arranged
for a system of internal audit of its offices.
In accordance to these instructions, each Ministry has set up its own internal audit
organization within the offices of the Chief Controller of Accounts although the textbooks
in financial management had prescribed a strong system of internal audit in each
organization for many years. He added that the government is perhaps more
progressive than the corporate world in institutionalizing this as a part of the financial
management system of the Ministries.
The scope and functions of the internal audit wings were to depend on the nature of
work, the quantum of the subordinate officers, number of subordinate offices, the string
to the establishment, the quantum of expenditure and so on. Each Ministry was asked to
draw up a specific manual of internal audit specifying the duties and functions of the
organization with reference to the particular peculiarities of those Ministries and the
various schemes of the Ministries and the Departments.
The idea of all this was to identify the specific risks in each scheme or program and to
build this into the audit manuals. At that time this technology of risk-based audit was not
in vogue. Most of the Ministries have formulated some sort of an internal audit manual,
and some are yet to do so.
The scope of internal audit has been specified in the Civil Accounts Manual. The
inspection code issued by the CGA in 1988 also lays down extensively scope and extent
of internal audits, the nature of checks to be exercised, the nature of detailed audit of
initial and subsidiary account records. The code also lays down the full scope of audit of
trained accounts officers when CGA inspects the trained accounts officer, what needs to
be done.
He mentioned the internal audit wings had full powers to examine the financial records of
all drawing and disbursing officers as well as other officers. In fact this power has been
extended to cover some of the autonomous organizations and the non-government
organizations.
3
Moving on, he said that internal audit has been perceived largely as a policing activity
whose main function is to find fault and to curtail and crosscheck rather than to find
solutions by way of recommendations. Consequently, the reports produced are dull and
not user friendly.
The inspection code issued by the CGA requires the internal audit wings to go into the
extent, frequency and controls/checks exercised by the administrative officers with a
view to locate any lacunae in procedures leading to fraud. They were also to check the
procedures for sanctioning expenditure for purchases, disposal of assets, and office
management procedures having financial and accounting implications. The purpose of
these exercises as specified in the code was to suggest tips to tighten up the
administrative and financial control systems within the organizations.
He then came to the current thinking globally, which is to enhance performance of
government organization with regard to delivery of programs and citizen services. The
perception has been that the financial control systems and procedures have been
confined to issues of complaints with rules and procedures rather than delivery of
program content, outputs and outcomes. These have led to the modern concepts of
value for money audit or efficiency audit.
According to Shri Sundaramurti, some of the Ministries have made a positive
contribution in this area. For the future, they should seek more work in these areas
without any dilution of the basic bread and butter aspect of internal audit. On the areas
which have not yet received adequate information, like audit of computerized accounting
systems, we need to get going. In particular he mentioned the context that the CGA has
embarked on an ambitious project covering all account offices. Training of the staff is
essential in audit of computerized systems. It requires training on basic computerization
aspects, accounting and on computer audit aspects.
Lastly, he lamented the fact that somehow the internal audit wings have become
punishment posting in the accounts offices. In fact, some offices indeed use it to that
effect. People are unwilling to be posted in the internal audit wings, as they have to
travel frequently and be out and lead a fairly unsettled life. They have to go all over the
country. The staffs are also quite unmotivated, as they see the whole thing as a futile
exercise.
He concluded the session by saying that the whole perception about the wing including
the performance expected of them would need to change. The Secretaries in the
Ministries would need to provide a direction particularly in the context of the current
emphasis of government on outcome budgeting, then again the initiative for change to
come from within the organizations of the chief controllers or accounts. They will have to
take the lead and kind of indicate the direction in which we could move from here.
4
Important recommendations:
• The emphasis of internal audit in the Defence Accounts Department is currently on
regularity and transaction audit.
• There is now a move being made towards management audit and risk audit.
• The ambit is also being broadened to include activity costing to facilitate
management to understand the cost of their decisions from the data that is
generated
• Internal audit is currently confined to largely transaction, procedural or compliance
audit.
• Internal audit has failed to suggest steps to tighten the administrative and financial
control systems.
• Modern concepts of “value for money’, monitoring and evaluation, efficiency etc.
are unaddressed.
• Internal audit is constrained by lack of adequate manpower, financial resources,
motivation and training.
• The initiative to strengthen Internal Audit has to come from the top administrative
level.
5
Session III
Client Expectations from Internal Audit in the Government of India
The third session of the Seminar was addressed by Shri C Balakrishna, Additional
Secretary and Financial Advisor Ministry of Shipping, Road Transport and Highways,
and by Shri Kanwal Nath, Deputy C&AG and Chairperson, Government Accounting
Standards Advisory Board (GASAB)
Shri C Balakrishna opened the session, by saying that internal audit should help and
assist management in maximizing opportunities, minimizing threats, and ensuring
optimum utilization of all resources, that is financial, human, and material resources. He
also added that it should contribute to the continuous improvement of strategies of
internal controls, management processes, risk management and internal systems
reviews and also include elements of performance reporting in order to increase overall
effectiveness. Internal audit should concentrate on ensuring that every transaction meets
the triple touchstone of procedural purity, financial propriety, and proper accounting and
utilization of the resources for the purpose it is intended.
Narrating his own experience with internal audit at the Ministry of Surface Transport and
Highways, he stated that internal audit has so far only been involved in carrying out
routine checks of financial and operational management activities. With the increased
complexities of technology and financial complexities, the changes in internal audit have
unfortunately not kept pace.
He added that the road sector has evolved considerably in terms of engineering
technology and financial complexities. Internal auditors therefore are required to
comprehend these changes and form their opinions about many of these important
areas including cost benefit, process flows, value additions, and appreciation of
internationally comparable processes and how, if at all these may be adopted in the
Indian scenario.
He pointed out that the internal audit of the ministry had so far not made any serious
comments on the relationship between the cost of construction and the changing use of
the road construction material. This is due to the fact that not many of us are trained to
appreciate the technical and financial aspects of the ministry in which we are functioning,
but it is incumbent upon us to try and make the best effort that we can to understand the
complexities and to use the specialized bodies for assistance wherever such internal
audit exercises are to be carried out. For a healthy feedback, therefore, it is essential
that internal auditors are properly trained and that we develop a pool of technically
qualified people to provide us with inputs in the various areas including management,
due diligence of systems and procedures, compliance of laws and regulations, and the
investing cases of serious financial irregularities
.
1
He was critical of the internal audit experience at NHAI, which he found to be far below
expectations. Their reports have been confined to routine aspects, because of which
perhaps the management of NHAI has not giving due importance to internal audit. The
internal audit exercises that have been carried on both in the ministry and the NHAI had
repeatedly thrown up the same kind of answers viz. of deficient planning, inefficient
contract management, and imprecise terms of contract with the design consultants etc.
He suggested that we need to move to managing our system so that the internal audit
function gives us proper input which we can then feed not only into our planning process
but also implementation, monitoring and concurrent evaluation making these systems
more scientific as well as expediting the fixing of responsibility.
The second speaker for the session, Shri Kanwal Nath began with the INTOSAI
definition of control, which refers to the control exercised by the senior management in
ensuring the effectiveness and efficiency of its operations whereas internal audit is the
control of all controls.
. The definition of internal control should also be extended by including the executing of
orderly ethical, economical, efficient and effective operations in place of only economy
and efficiency of operations including achievement of performance scores. In this, Ethics
should be made an important control objective because ethical behavior by a public
servant is considered the key stone of good governance.
He said that even though we have procedures for everything, we lack a formal
mechanism in the shape of an act or a policy document for internal control which is
closely related to the issue of accountability which COSO also mentions.
Presently in India, though there are internationally applicable standards and best
practices, internal audit continues to focus and report on relatively minor aberrations.
Internal audit seek to check accuracy of accounts, prevent and detect frauds, point out
irregularities, check initial accounts maintained in the executive offices and ascertains
the extent to which rules, regulations, systems and procedures in accounting and
financial matters are being followed.
He also raised some issues such as budgetary assumptions and processes, manpower
analysis, a review of programmes and schemes which have traditionally been in the
sphere of external audit, but should be at the internal audit level itself. He made an
important point that the Comptroller and Auditor General of India was extremely keen
that the internal audit of all the departments become as strong as possible. The audit of
autonomous bodies or the public sector undertakings which are under the ministry often
gets neglected, and this can be addressed by internal audit. While external audit refrains
from directly
2
commenting on policies of the government, internal audit has the inherent advantage
that it can help the management shape the policies.
Manpower is, however, a serious constraint and this has to be immediately addressed.
The skills definitely need to be upgraded through training and the skills of the service
officers and of the accounts officers and staff become very crucial as they are on the
cutting edge.
The need for conducting periodic evaluation of the adequacy of internal control
mechanisms is also something which we ought to do because that would keep us up-to-
date with where we should be. He mentioned that the C&AG had introduced a chapter
on internal control in the audit reports of the state governments. For the central
ministries too, the CAG were proposing to examine the efficacy of internal control, as
they felt that any good system of internal control should comprise a proper allocation of
the functional responsibilities within the organization. He said that proper operating and
accounting procedures should be in place so that accuracy and reliability of accounting
data, efficiency in operation and safeguarding of assets is ensured. Quality of personnel
should be commensurate with their responsibilities and duties. Another step could be
review of the work of one individual by another whereby possibility of fraud or error due
to collusion is minimized.
Finally, he said that internal audit should extend its ambit to cost benefit analyses,
utilization and deployment of resources, matters of propriety and most importantly the
effectiveness of the management since internal audit is meant to be essentially an aid to
management.
Important recommendations:
• Internal audit should assist management in maximizing opportunities, minimizing
the threats, and ensuring optimum utilization of resources.
• Internal auditors have to keep pace with the changes and complexity in terms of
technological and financial complexity by ensuring proper training.
• There has to be stress on concurrent evaluation so that internal audit feeds into the
processes of planning, implementation, and monitoring.
• The definition of internal controls needs to be broadened to include orderly, ethical
economical, efficient and effective operations including achievement of
performance scores.
• Internal audit is negative in its orientation and focuses on relatively minor
aberrations that are largely regulatory and compliance in nature.
3
• Issues which have traditionally been the focus of external audit need to be taken up
by internal audit such as budgetary processes, manpower analysis, reviews of
manpower programmes and schemes and audit of autonomous bodies etc.
• Skill up gradation and training of both the officers and the staff, who are at the
cutting edge, is of critical importance.
• Internal audit must conduct periodic evaluation of the adequacy of internal control
mechanisms.
• Internal audit should extend to cost benefit analysis, resource utilization and
deployment, propriety and effectiveness of management.
4
Session IV
Standards setting on Internal Audit: Applicability to Core Government
The panel speaker for the fourth session was Shri Ashok Haldia, Secretary of the
Institute of the Chartered Accountants of India (ICAI). He began with defining the scope
of internal audit, which consists of ensuring the adequate effectiv3Xess of internal
control systems, assessment of the effectiveness and integrity of management
information systems, safeguarding of assets, economical and efficient use of resources.
He said that conventionally, internal audit has been confined to the functioning of the
management and regulatory and compliance audit. However, of late it has changed to
include various types of audits, official audit, value for money audit, performance audit,
Programme audit, etc.
He pointed out that the present applicability of internal audit in core government in India
was limited to finding errors and irregularities, which is more of a negative aspect.
Internal audit should be adding value to the management, and to management functions.
He then came to the aspect of independence of the internal auditor. Internal audit must
have a mandate for its role and position in the Organizational hierarchy, which should
define its role, powers and reporting structure. The transfer and promotions of internal
auditors are controlled by the executive, which severely compromises their
independence. To carry out internal audit effectively we need to ensure the
independence of the internal auditors. As internal audit leads to accountability, the
management would have vested interest to see that the internal auditor is not in the right
place.
He then suggested that we must look into providing remedial measures in the standards
themselves, so that the system is insulated from the vagaries of individuals. Coming to
the issue of the bench marks to be set for performance of internal audit functions, he
commented that the conduct of internal audit with reference to a certain set of qualitative
standards should be mandated.
Internal audit has to prove itself to be of value to management. This can only be
achieved, when those who perform the internal audit function do it diligently.
Shri. Ashok Haldia concluded by briefly addressing the crucial issue of capacity building
for the purpose of standard setting, for providing implementation guidance and for
implementation of the standards.
1
Important Recommendations:
• Internal audit in government has a negative orientation in terms finding errors and
irregularities. It needs to add value to government
• Independence of the internal auditor from the executive is of critical importance to
the success of internal audit.
• Capacity building is the need of the hour for an effective and strong internal audit.
2
Session V
Client Expectations from Internal Audit in the Government of India
The panel speakers for the fifth session were Mrs. Veena Upadhyaya, Joint Secretary,
Ministry of Environment and Forest and Shri S P Pal, Advisor, Program Evaluation,
Planning Commission.
Commencing the session, Mrs. Upadhayaya described the evolution of the word audit,
which according to the Oxford Learners is defined “as official examination of accounts”.
A subsequent edition of the dictionary defined the word as “official examination of
financial records”. Again, another meaning of ‘audit’ was “official examination of quality
or standards of something”. Finally, the 2002 edition had evolved the word as
“systematic review or assessment of something”.
Keeping the evolution of the word in mind, she then began with the client expectations
from internal audit in the government, and she addressed the significant developments
on the macro level financial scenario had very distinctly stressed on outputs and
outcomes.
She said that the Fiscal Responsibility and Budget Management Act of 2003 underlines
the need for effectiveness of financial governance through decentralization, and the
enactment of Right to Information Act has only taken it forward. With stress on outputs
and outcomes, on decentralization for more effective financial governance, and
emphasis on accountability and transparency within the framework of Right to
Information Act, the whole financial ambience governing the country has changed. There
is a distinct stress on good governance on forums like the Inter-State Council, the
National Development Council, etc. There is a clear emphasis on good governance, on
ethics, on equity, on efficiency and in order to achieve it, on electronic governance for
improved efficiency.
She then described her experience in the Ministry of Environment & Forests, where the
management has opted for e-governance in the Ministry. She said that an extremely
comprehensive, deep, wide, and 360-degree purview had gone into the e-governance
project. There is a clear emphasis on outputs and outcomes. Therefore, she asked that
in this scenario, what do we expect from internal audit? As a client organization, she had
the expectations that audit would transcend beyond financial and accounts and would
encompass the entire domain of governance.
Coming to the financial and physical performance levels, Mrs Upadhyaya mentioned that
the distinction between financial and physical is rather modernist. One should really look
at performance and that should be inclusive of financial and physical. It is the
performance audit, which should really be in the driving seat. The auditors should not
just be examining the standards and qualities, but audit should lay down standards and
norms, to play a more proactive role. It should not just ensure a meaning to standards,
but take a proactive advocacy of
1
those norms. The audit should be formulating and refining these standards and norms
on a rolling basis and not as a one time exercise. Auditors should be expected to be a
partners, collaborators, guides and mentors in formulation of standards and ensuring
good governance.
This, she said, would require a major paradigm shift from the existing perception of its
role, and the paradigm shift will involve a major restructuring and upgradation of the
skills. Audit has to acquire a tremendous reach and depth, incisiveness and
assertiveness.
She then shared her experience at the MoEF, which has a major scheme like National
Afforestation Program. It was restructured by resorting to decentralization by giving
powers to the people, entities in the villages called Joint Forest Management
Committees. The money goes directly to the Forest Development Agencies, which
operate at the DFO (Divisional Forest Officer) level. The funds do not route through the
state exchequer, which is a major change in any government. However, a closer look at
the decentralization process revealed that the decentralization was not complete. There
continues to be extreme centralization in so far as routing of things to the principle chief
conservator forest is concerned. For each little release or advancement in the
implementation of the scheme the DFO has to route all his papers through the PCCF.
It was for the auditor in the ministry to point this out, to take up the examination of this
much wanted decentralization; point out the areas where decentralization was weak,
however, audit did not do the required job.
In a related area, the functioning of the DFO officers could be scrutinized. For the record
she mentioned that the DFO office had no finance and accounts officer. Lot of money
flows through that office, but the DFO is the DDO himself. She added that audit should
insist that there should be a finance and accounts officer handling the funds. She also
mentioned that the cost incurred on having that institution will be just a fraction of the
benefit that will accrue in ensuring better utilization of funds.
Addressing this issue to the CGA, she said that we need to link releases with outputs,
and with productivity levels achieved. The sanction letters should be redrafted, and it
should indicate all the physical outputs and outcomes to be achiever, and also give the
milestones of productivity with which the next installment is to be linked.
She again added that these initiatives should ideally be coming from audit. Taking
another example, she said that MOU’s signed with NGOs and autonomous institutions at
times are exceedingly amorphous and general. They do not spell out the obligations of
the players involved. The audit should also be associated with the business process
reengineering of MOUs and contracts.
2
Further mentioning the areas where audit can play an exceedingly efficient role in
ensuring that delivery is effective are the Evaluation norms, consisting of concurrent
evaluation, terminal evaluation, monitoring, etc. She made an important point that we
should try to reach a stage where statuary audit becomes gradually dispensable.
Pushing ahead, she then insisted that a new mantle needs to be donned; the new
auditor in the current scenario needs to be more of a manager, standard setter, needs to
be IT savvy to keep pace with the developments in e-governance to be able to advise
what systems are to be adopted. We need to upgrade the skills and most of all we need
to have more effective interface at the highest levels.
Lastly, she lamented the existing perception of audit where is the exercise of audit starts
with the LDC and ends with the SO. Hoping for an early change in the situation, she
concluded by suggesting that the levels of communication should be upgraded. There
should be effective interface at the senior most levels, so that we together jointly can
deliver good governance to the people at large.
Carrying the session forward, Shri S P Pal began with slightly changing his topic to
expectation from internal audit rather than client’s expectation, because according to
him, the relationship is not between client and provider or, master and subordinate or
customer and seller, but we are all partners in the development process.
He then defined the premise of his talk, which was related to development planning and
implementation, with particular reference to development fund authorization, allocation
and spending, thus establishing causal linkages between inputs, output, activities and
outcome.
Setting the premise, he came to the point that the people who are involved in the fund
flow authorization are basically the parliament and the legislature, or in other words, the
policy makers. They expect that the development interventions bring intended impact
and outcome. They want to achieve this through the interventions, program goals and
intended development changes.
At the second level, those who allocate fund, for example, Planning Commission and the
Finance Ministry expect that the effectiveness in program design and implementation
should come from experience, because they are planning and implementing
development programs in uncertainty.
Finally, those who release fund, the line ministries and the departments want to get
adequate resources in time so as to initiate planned activities and attain targets.
So when we make development interventions we follow a systematic way, which says
that to achieve certain goal we need certain inputs, activities and certain outputs. Inputs
here mean all kinds of inputs, financial inputs, human and material resources, as well as
infrastructure. Activities meant tasks undertaken by the staff who transforms inputs into
outputs. And we all are supposed to
3
produce certain product and services and help the planners and implementers to
achieve the development goals of the country. In this broader context we need to
examine the expectations from the auditor.
To elaborate his point, he took up the example of the Planning Commission, where a
PEO (Programme Evaluating Officer) is supposed to help the government and planners,
or the policy makers, to improve policy and program formulation process through
feedback from evaluation. The government had established PEO primarily to understand
ways to improve policy and program design. The outcome from PEO’s activities would
be post correction, and the output of PEO would be quality an evaluation report, which
will offer transferable and implementable lessons. However, this office is grossly
underutilized, which causes a colossal waste of precious public money, apart from
compromising the quality and performance of the parent organisation.
Contrary to the present views, and in his experience, all monitoring and evaluation
activities cannot be outsourced; and monitoring and evaluation is often input to the
planning and implementing process. Further substantiating his point, he added that
many outside organizations do not have access to the process data. Internal
government organizations, which can facilitate and use process data in monitoring and
evaluation, should be used to improving the methods of doing governments business
under changing circumstances, changing conditions. We should move away from
managing inputs to managing outcomes under changing scenario.
He then introduced another concept to move away from the standard performance
measurement of economy efficiency and effectiveness (3E’s) to something like
diagnosis, design and develop (3D’s)
By diagnosis he meant that the problems are diagnosed confronting the particular
ministry or particular division or particular unit that is implementing a government
program. Design referred to designing a strategy to address those problems which have
been understood. And in the process of getting involved along with the agency, whatever
the agency is doing, the auditor should get involved in the process and then develop
capacity of their own as well as of the implementing agency to solve problems and be
flexible.
In summary and conclusion, he said that accountability under the new circumstances
must undergo major changes. The role of the Finance Ministry or Internal Audit is
reactive currently; it should be now proactive to re-award adaptive behavior and
guidance. The spending agencies and the auditors should work together to optimize
within the overall budgetary constraints. At the macro level the Finance Minister is
saying that the budget deficit will be no more than 4% of GDP. The constraints are
given, so there neither the auditor nor the implementing agencies can stretch
themselves, and they have to accept that as a given parameter. However, within that
parameter it is possible to device new strategies to optimize. Both auditors and the
implementing agencies should work
4
for attaining the organizational goal, both should measure and monitor performance like
output, outcome and impact. The auditor should not be concerned only with rules and
regulations, but should rise above that. For attaining the organizational goal, outcomes
and overall development should be as much as auditor’s responsibility as that of the
implementing agency’s. Both should work for strengthening the link between
performance monitoring, budgeting and evaluation. Both should work for trust through
cooperative bargaining in the budget process rather than just imposing one’s wish on the
other.
Important Recommendations:
• The dictionary definition of ‘audit’ has evolved to mean ”systematic review or
assessment of something”
• Audit should transcend beyond financial and accounts and should encompass the
entire domain of governance.
• Audit should be formulating and refining standards and norms on a rolling basis and
not as a one time exercise.
• The new auditor needs to be more of a manager, standard setter, and be IT savvy.
• All monitoring and evaluation activities cannot be outsourced; they have to be
carried out in-house.
• To achieve the organizational goal, outcomes and overall development should be
as much as auditor’s responsibility as that of the implementing agency’s.
5
Session VI
Bridging the Gap: Issues and Challenges
Addressing the Seminar for the second time in the sixth session, Ms. Carman Young
began with briefly summarizing the composition and the structure of the World Bank,
which has five organizations. These are the IBRD, which started in 1944, the
International Development Association, which is the grant-providing organization, the
International Finance Corporation, which manages the private sector initiatives, the
MIGA, which is Multilateral Investment Guarantee Agency and another very small
agency whose role is to settle investment disputes and promote international
development. Speaking about her organisation, she mentioned she heads the Internal
Audit Organization for all five of those organizations. The Bank has 184 member
countries, and there are offices in more than 100 countries. The total lending of IBRD
and IDA for fiscal year ’05 was US$22 billion. This was to give a rough idea about the
scale of operations her establishment has to oversee.
She made a point that internal audit for any organisation should make information
available, with five specific objectives for financial and operational ease, and that
information should be accurate, timely, and reliable and should have integrity so that it
can support decision making. Also, it should make sure that resources are acquired
economically and used efficiently to safeguard the assets and it includes human,
physical, and financial and information assets, to make sure that the actions are in
compliance with not only laws and regulations, but also policies, procedures and
contracts.
Therefore, everything that internal audit does should be driven by business objectives of
the unit or the program or the process internal audit examines. The fundamental idea is
for the internal audit to get involved as those systems are being implemented to
recommend changes in internal control that can be developed into systems, and not just
be an add-on at the end.
Speaking about her organizational role, she said that they report directly to the President
and that gave them independence that they needed, hence making the point that the
highest authority should directly be involved in audit reporting. However, she added that
their they made sure that it was the management’s prerogative to accept risk, and it was
left to the internal audit to make sure that they communicate the level of risk the
management is taking, while also making sure that they understand what they are
accepting in terms of risk.
Deliberating further on her organisation, she said that she had four groups that are
responsible for audits. Corporate service is a group that looks after all of the audits in the
finance complex, treasury operations, human resources, and other service parts of the
organization. Another group was development operations, which looks at the major
development programs. The third was the country operations group which was a unit
that looks after audits in the country offices.
1
She said that although they have significantly reduced the numbers of total audits
undertaken, they now focus on more risky parts of the business. Finally, the fourth is a
small IT group that looks after audits of infrastructure and platforms and contingency
planning.
She mentioned quality control is a must for audit, and that they had an external quality
assessment of the internal audit function. The IIA standards now require this
assessment at least one in every five years. Her group has used the quality assessment
as a supportive measure to pursue change in the mandate of audit function.
Coming to the aspect of ownership, she revealed that the US holds greater percentage
of the share than any other shareholder, which is about 13% of ownership in the World
Bank. Hence, the US legislature has considerable influence, and certain bills have been
passed that links US appropriations to some conditions and one bill requires
comprehensive assessment of internal controls of the Bank.
She then narrated the experience in the Canadian government, where in 1984 a
legislation was passed for semi-autonomous crown corporations to have a
comprehensive assessment of internal controls by the external auditor, once every five
years. The internal audit was required to develop its processes so well that the external
auditor could rely on its work
The internal audit group at the Bank wanted to emulate the Canadian model, and this
was met with a lot of resistance by the US Treasury, the Legislature, but slowly internal
audit won its ground. In a bid to upgrade the skills and the infrastructure, the Bank had
introduced SAP as the ERP system for keeping track of the books in the finance
operations, and they were able to identify about 100 business processes that needed
immediate attention.
The next step the audit undertook was to identify all of the business processes with high-
risk ratings and they all were included in the audit plan. They also had to introduce some
methodology changes to ensure that all of the auditors were using a consistent method
in the audit. The internal audit used the COSO enterprises management framework as
the evaluation matrix for making sure that they cover the same aspect of every
operation, and the conclusion of every aspect of COSO-ERM for each audit. They used
traditional risk and control matrices to review control activities, which were also normal
internal controls or control activities that were intended to manage risks. Finally, they
coordinated the process and unit audits to make sure that they were sequenced.
As a secondary step, they also strengthened our internal reviews. For every audit, after
conducting the preliminary planning phase the auditors had to meet the audit
management team. Then the audit team went through the audit approach and the
sampling plan, the risk evaluation matrices, and the risks that were being looked at, and
hence the management team knew what was happening in every audit.
2
In a reciprocating measure, at the end of the audit, the audit team came back to the
management team and discussed the results of all of the audit work and everyone had
to come to a consensus as a management team on how significant were the
deficiencies, how strong were the controls so that all members of the audit department
understood how audit was undertaken and results actually achieved.
This created a healthy atmosphere of learning, where the members were learning more
about the entire organization with every project that the audit undertook, and this
strengthened the internal quality assurance processes and we trained every one of the
staff members on quality assessment. Importantly, the whole internal audit staff took the
IIA training to become an internal assessor and validator for quality in an audit function,
and this had ensured the standards of audit were duly maintained in the World Bank.
Next in the session, Mr. Thomas Warga, began with introducing an internal audit study
for identifying top ten challenges facing the public sector, which were found to be
consistent around the world. These were adequate staffing, compensation of the staff,
ability to measure performance, adequate technology resources, ability to report results
timely, the ability to benchmark the work, promoting effective internal governance within
the organization, establishing a risk-based plan for the audit, ability to bring in expertise
to supplement the audit staff, and adequate resources for continuing education.
Highlighting this, he went on to possible solutions. As far as adequate internal audit staff
is concerned, we have to look at sharing resources between other agencies. Co-
sourcing, going outside the organization, and leveraging of technology are possible
solutions to this conundrum.
In the long term, the idea could be to increase the supply of people into the profession.
For this to take effect, the IIA is partnering with universities around the world in providing
them with internal audit curriculum and materials.
Coming to the perpetual question of motivation, he said that there are alternative
strategies like money, however not everybody is motivated by money. It’s not just salary
that motivates people; there are other things as well.
For measuring performance, it’s always better to start with the customer to determine
their expectations in order to measure the outputs. Benchmarking inside the
organizations is helpful to determine measures of performance, and it should always be
result based.
He also made an important point that Co-sourcing or outsourcing only works if the task is
very specific.
Coming to the issue of reporting, he said that the results should be reported timely;
however, report writing usually is the stumbling block, and report writing skill training is
very crucial.
3
Talking about the important issue of benchmarking, he said that audit departments
should make sure that every aspect should be benchmarked against what is the current
practice in other organizations, including promoting effective corporate governance or
effective governance within the organizations
He then said that risk-based audit plan is an excellent approach. The risk should be
measured at two levels; in the overall audit plan, and while the actual engagement is
undertaken
Finally, concluding the session, he came to the issue of training, which was always
found to be very important for the internal audit profession, to keep people current in
their profession, in the content of auditing. The training in basic report writing, audit
skills, content skills should be formalized.
Important Recommendations:
• The audit information should be accurate, timely, and reliable and should have
integrity so that it can support decision making.
• The Management should have an external quality assessment of the internal audit
function.
• According to a study, top ten crucial issues facing the internal audit in public sector
could be listed as:
i. adequate staffing,
ii. compensation of the staff,
iii. ability to measure performance,
iv. adequate technology resources,
v. ability to report results timely,
vi. ability to benchmark the work,
vii. promoting effective internal governance within the organization,
viii. establishing a risk-based plan for the audit,
ix. ability to bring in expertise to supplement the audit staff,
x. Adequate resources for continuing education.
• Co-sourcing or outsourcing of internal audit only succeeds if the task is very
specific.
• Internal audit results should be reported timely; and report writing is very crucial for
internal audit.
• Benchmarking of standards within the organizations is helpful to determine
measures of performance.
• The most important aspect for internal auditor is continuing training, to keep people
current in their profession, in the content of auditing. Training in basic report
writing, audit skills, and content skills should be formalized.
4
Session VII
Review and General Discussion
The last session was an overall review of the proceedings of the Seminar, and a
general discussion on the more pertinent issues. Shri G P Gupta, CCA, M/o Finance
gave a presentation summarizing the proceedings of the Seminar, and gave an
introduction to the pilot project on internal audit in the M/o Environment and Forests. The
distinguished speakers on the dais were Dr. Adarsh Kishore, Finance Secretary to
Government of India, Shri S W Oak, Controller General of Accounts, and Ms. Carman L
Young, Auditor General, The World Bank,
Shri G P Gupta began the session by addressing the current status of internal
audit in the various ministries and departments. He commented that we have primarily
confined ourselves to compliance audit or to regulatory audit. Elaborating upon the
compliance audit, which is akin to transaction audit rather than systems audit he
regretted the fact that internal audit is not considered important.
He then described the pilot project in the Ministry of Environment and Forest, and
the reasons for selecting this particular Ministry for Pilot Project. The first important
reason was that the top management was willing to be a party to the project, thus
addressing the basic issue of ownership. Also, the Ministry had the combination of
dealing with the state governments, the autonomous bodies, public sector undertakings,
and also with the non-governmental organizations, or NGOs. In sum, the Ministry would
cater all the dimensions of the governance and one could try out different schemes
which would work in different entities of semi-government, the government and the non-
governmental organizations. Another reason was that the Ministry of Environment and
Forest had been working on an e-governance project. Further discussions with the
consultants revealed that it would fit into the overall e-governance Project to define the
controls, scope and revised mandate of internal audit in this Ministry.
He then began to sum up the lessons learnt in the two days of the Seminar, and
particularly highlighting client expectations from internal Audit as brought out by Mrs.
Veena Upadhyaya, Joint Secretary, Ministry of
1
Environment and Forests. She had drawn attention to the interesting evolution of
the word audit where the first definition of audit was ‘official examination of accounts’
which moved on to ‘official examination of financial records’, and then further to ‘official
examination of quality or standards of something’. This, she said, meant for a
requirement to set the standards and one needed to examine the results with reference
to the preset standards or the benchmark and then finally have a systematic review or
assessment of programmes and activities completed. The scope of audit in her
assessment was something, which is quite different than what we are doing today; the
audit to transcend the domain of finance and accounts to embrace and encompass the
entire domain of governance. Moreover, she stated that audit is not merely ensuring
adherence to standards but taking a proactive advocacy, formulation of standards, and
refinement on a continuous basis.
Shri Gupta then went on to address the recently introduced outcome budget, and
its format containing the risk parameters, risk assessment, risk identification, where each
parameter needs to be independently assessed and reported in a timely manner, leaving
enough time for mid course corrections. The risk analysis flows from the outcome
budget, which demands a move from transaction or compliance audit to program or
scheme audit.
He then summarized the session by Shri. S.P. Pal, Advisor, Planning
Commission who had earlier introduced the 3Ds of diagnosis, design, and development,
and how they aptly apply to internal audit in the Government. Today in the Government,
there is a severe resource crunch, both in terms of the quality and the quantity, which
has to be addressed with requisite skills. Internal audit needs to be assertive and
incisive, and it cannot be seen as a conflicting entity with external audit. There is no
conflict between these two sets, which generally seems to be the perception at times.
Internal audit needs to be a participative process and not a fault finding exercise. The
operational policy has to be drawn in consultation with the executive.
Shri. Gupta finally referred to the Capability-Maturity Matrix which Ms Carman Young
had earlier explained in the first session of the Seminar. He then requested Ms. Young
to once again elaborate the concept of the matrix, for the benefit of the Finance
Secretary.
2
Following the presentation by Ms. Young, Shri S W Oak, CGA addressed the gathering,
and brought out the need to make a 360-degree turn in the role of internal audit. He said
that it had been supply driven because so far it had just been checking the compliance
of procedures and records set earlier. It should ideally be demand driven.
He also mentioned the outcome budget; where the last column mentions risk
factors. Here, internal audit could be given the role of monitoring these risk factors on an
ongoing basis. There was yet another important phase of implementation, which
questions whether the monitoring and evaluation systems, which have been laid down
are adequate and serve the purpose.
CGA then highlighted the important issues of empowerment and ownership,
which for him were the core of the matter. He also brought out the important point of lack
of legislative framework and indicated that internal audit is not even mentioned in the
Allocation of business rules. He expressed his concerns on the quality aspects which
need to be addressed through skill up-gradation, training etc.
CGA finally referred to the dichotomy between internal and external audit, and
said that he was pleasantly surprised to find that the deputy CAG was willing to give
performance audit role to internal audit. The C&AG had also expressed his concern on
strengthening of internal audit.
Dr. Adarsh Kishore, Finance Secretary also addressed the gathering in the
concluding session. He commenced his address by mentioning that the international
best practices and existing standards should be examined in terms of their possibility of
being replicated with improvements and adaptation in India. He said that a simple
expenditure audit, which is constitutionally mandated essentially for the post expenditure
audit is not adequate. There is a very, very healthy realization today in the entire country
and indeed particularly so in the finance and accounts community of our country that it is
not enough to have handsome provisions only; what is important is satisfactory
outcomes.
He strongly felt that the time had come when we move away from the
perfunctory, more formal than substantial compliance of the discipline “of our
expenditure norms.” It is not merely the sheer volume of expenditure that has grown but
the entire processes of the government have changed fundamentally and that brings in
the element of complexity in the kind of audit we have at
3
present. Therefore there is no debate on the need to revisit the entire concept
and its relevance with changed requirement, identification of the change, and the pace of
change in the entire concept structure, procedures, and the mandate.
That, he said, brings us to the question of ownership. The role of internal audit to
be redefined must be owned with a fresh mandate by the government. The second
aspect of the ownership is that the internal auditors own what they are contributing in
terms of their advice and actions vis a vis the executive. Redefining internal audit will
have to be a process which has a collaborative and cooperative understanding in the
whole matter. At every stage the ownership will entail and will demand that one adds
value to the process of implementation in terms of its probity, in terms of its
transparency, and in terms of its quality and that cumulative effect is transformed as it
were, into a better design.
He further said that if there is a thesis and an anti-thesis they must converge, by
conflict, into a synthesis, which itself at the higher stage of evolution becomes a thesis
giving a confrontational position with another anti-thesis and giving rise to yet another
superior synthesis and so on. The whole process is evolutionary. The dialectics of our
internal audit ought to be that while one appears to be presenting an adversarial view, a
view which does not strengthen the other’s sense of comfort with what they have done.
In fact it introduces a minor agitation in the other’s mind, which is healthy, which is
positive, which is encouraging and the two sit down and give rise to something, which
contains the seeds of both and emerge as a superior product then the one, which was
subjected to audit.
That, he said, takes one to the third issue of mandate. The efficacious functioning
and advice of internal audit will be only as good as it is formally mandated. As a part of
the system whether it is an executive fiat or it is a legislative mandate, it can still be a
part of the process. The mandate has to come from the highest level of government,
either suo-moto or as legislated by the parliament. That’s a matter of detail but the
mandate remains important and he announced that he would undertake to set in motion
a process, which would result in a formal mandate for internal audit as an integral part of
the management of the finances of this country.
4
He then very generously asked the CGA to draw upon the talent, expertise and
the experience that might be available overseas and internally in the country, in the
academia, in the private sector, and the public sector to draw upon a revised mandate.
For this he put forth a sum of Rupees 100 million during this fiscal to kick start the
process.
He then expressed his gratefulness to the World Bank for having given the
intellectual and financial support and also mentioned that while the path has been
shown, the need has been highlighted; we can now take over the baton from them. For
this, he reiterated that there is no constraint of resources. He suggested that CGA may
send four or five small groups for interacting with the corresponding functionaries abroad
and see what the best practices that are being talked about. For this he gave his
assurance for a most favorable and sympathetic consideration at the highest level, and
he made it his responsibility to see that before the fiscal is out, CGA will have a formal
mandate in the charter of responsibility to begin with.
That, he said brings us to yet another question of evolution of this concept, as
very succinctly recapitulated earlier. He referred to the earlier used expression of
‘transcendence of accounts and finance’. He said that the transcendence should not
ultimately result in levitation that one just rises above the whole thing; we must be firmly
grounded into what the accounts and finances are, because it is ultimately the line
ministries’ responsibility to ensure that not only is the money utilized but it also gives
best value for money.
He then briefly commented upon the evolution and growth in the concept of
budget in India, which has changed from the constitutionally mandated annual financial
statement to the performance budget and now the recently introduced outcome budget.
There is an organic and harmonious relationship between these different kinds of
budget.
The outcome budget is mandated to capture the deliverables flowing from the
provisions presented in the annual financial statement. We must be prepared and
eternally vigilant to see that the deliverables are delivered.
He added that this country is running and doing well because of the unsung, and silent,
dedicated workers who are doing their job well, in a sincere clean fashion.
5
We must expand and formalize our systemic arrangements by addressing the issues
such as the relationship with the financial advisor, the program evaluation organization
of Planning Commission, external audit and finally with the executive. He concluded with
three pertinent sentences, which are reproduced verbatim:
i. One: today we will disperse with a determination to make internal audit more
efficient, value adding, and formally mandated in the governance of this country.
ii. Two: that we will build our capacity to do things better with skills which may not
exist with us today; for this we will tap both national and international resources
iii. Third: the negative perception, which sometimes get attached to finance people
would soon be turned into a matter of the past and people shall look at us as a
resource, as a human capital, that is adding value not only to the concept or
design of schemes but also in their implementation in order that we hand over to
the next generation a better government, and a better India.
Traditionally, internal audit has been viewed negatively in orientation because it centered on reporting minor regulatory and compliance issues, often uncovering small-scale errors or procedural lapses without broader strategic input. This perspective is changing as internal audits now aim to add value by assisting management in maximizing opportunities, minimizing threats, and ensuring optimal resource utilization. The scope is being broadened to include performance audits, cost-benefit analyses, and the effective use of resources, indicating a shift towards a more proactive, strategically involved role .
Maintaining auditor independence is challenging due to potential conflicts of interest from close auditor-client relationships, non-audit services, and independence in appearances. To address these challenges, standards have evolved to incorporate declarations of independence, prohibitions on certain relationships, and the establishment of oversight boards. These standards aim to ensure objectivity by structurally separating audit functions from non-audit roles and require transparent communication of independence status to stakeholders .
The evolution of auditing in the USA from the 1920s to the 1960s was heavily influenced by several significant historical events. The 1929 Wall Street Crash and the Great Depression prompted increased investment in business entities, which in turn led to the development of capital markets. As companies grew in size, the separation of ownership and management functions became more distinct, necessitating a more rigorous audit to ensure integrity in financial statements. Additionally, the enactment of the Securities and Exchange Commission Act of 1934 established mandatory audits for profit and loss accounts, further shaping the direction of auditing practices .
Internal audit plays a supportive role in developing government policies by providing management with inputs on financial and performance data, which helps shape policy decisions. Unlike external audits, which often refrain from policy commentary and focus on compliance, internal audits can directly influence management decisions and policy formulation through their ongoing review and feedback mechanisms. This involves not only identifying errors or inefficiencies but also suggesting improvements for effective resource management and operational efficiency .
With advancements in the securities markets during the mid-20th century, the audit approach evolved in several ways. There was increased reliance on internal controls and sampling techniques, as large volumes of transactions made detailed verification impractical. The focus also shifted towards ensuring the truth and fairness of financial statements. Physical observation of assets and reliance on external evidence became more pronounced, reflecting a shift from simply verifying transactions to a broader assurance role that emphasized the overall integrity and reliability of financial reporting .
In response to the collapse of corporations, there were significant reforms in auditing to enhance independence and relevance. Recommendations included incorporating a statement in the Corporations Act for auditor independence, requiring declarations of independence to boards, prohibiting special auditor-client relationships, and establishing auditor independence boards. These changes sought to prevent conflicts of interest that could compromise audit effectiveness. The role of auditors evolved to focus on public interest, integrity of financial reports, and the need to separate audit and non-audit services .
During the period from the 1840s to the 1920s, the main objectives of auditing were the detection of fraud, detection of technical errors, and detection of errors of principle. These objectives were determined through legal precedents and guidebooks of the time. Court cases such as London and General Bank (1985) and Kingston Cotton Mill (1896) established the standard for audits focusing on the detection of errors and fraud. Lawrence R. Dicksee's 'A Practical Manual for Auditors' also emphasized these objectives .
The Joint Stock Companies Act of 1844 played a crucial role in the development of auditing in the UK. It required that company directors balance the company's books and prepare a full and fair balance sheet. Moreover, it appointed auditors to check the company's accounts, laying the foundation for auditing by creating a formal structure for financial accountability. This act marked the beginning of formal auditing processes by aligning the need for transparent financial disclosures with legal requirements, albeit audits and annual balance sheets for shareholders only became compulsory in 1900 under the Companies Act 1862 .
The historical shift in auditing from an 'enhancing role,' which focused primarily on improving the integrity and credibility of financial information, to a 'convergence role' implies a broader responsibility of auditors in public interest. It suggests that auditors are now expected to not only assure the accuracy of financial statements but also to identify business risks and advise on internal control environments. This shift is driven by the need to integrate more comprehensive audit practices that align with global standards and reforms following corporate collapses, enhancing the overall utility and trust in the profession .
The increased reliance on internal controls during the 1960s-1990s reflects an adaptation of audit procedures to the growing complexity and scale of business operations. As companies expanded in size and the volume of transactions increased, auditing shifted from verifying individual transactions to assessing robust internal control systems. Auditors started using analytical procedures more prominently and placed greater emphasis on understanding and documenting accounting systems, which demonstrated a change towards efficiency-focused audit approaches. This reliance on internal controls allowed auditors to perform more effective and efficient audits .